DRQ · data residency quarantine

DRQ independent AWS coverage

The AWS probe program ends at PROBE_END, 2026-10-23 (infra/aws-probe-model.ts). No scheduled job renews its collector credentials, which last up to seven days (infra/aws-probe-renew.ts); an operator may run infra/aws-probe-renew.ts by hand until then (#466). The ledger's nightly R2 check does not enroll new targets in this panel.

Issue #184. Owner authorised the complete wider measurement delivery, including scoped AWS provisioning and costs, on 23 September 2026. Existing DRQ remains operational. Price checks were recorded at 03:44–03:47 AEST. All eleven execution locations are now deployed; the expanded reference collector and combined geographic qualification are deployed under ADR-0045.

Geographic coverage

Eight regional probe locations plus three Local Zone locations cover eleven of the seventeen requested CF cities. Region or subnet identity establishes the AWS execution geography, not the storage location of a remote CF resource. Successful deployment and runtime identity checks are required before counting any source as operational.

City AWS execution location Instrument Deployment observation
Sydney ap-southeast-2 Lambda probe and regional reference Deployed; actual Lambda region verified
Melbourne ap-southeast-4 Lambda probe and regional reference Deployed; actual Lambda region verified
Perth ap-southeast-2-per-1a EC2 probe and reference endpoint Deployed; actual Local Zone and HTTP reply verified
Auckland ap-southeast-6 Lambda probe and regional reference Enabled and deployed; actual Lambda region verified
Singapore ap-southeast-1 Lambda probe and regional reference Deployed; actual Lambda region verified
Jakarta ap-southeast-3 Lambda probe and regional reference Enabled and deployed; actual Lambda region verified
Hyderabad ap-south-2 Lambda probe and regional reference Enabled and deployed; actual Lambda region verified
Hong Kong ap-east-1 Lambda probe and regional reference Enabled and deployed; actual Lambda region verified
Tokyo ap-northeast-1 Lambda probe and regional reference Deployed; actual Lambda region verified
Los Angeles us-west-2-lax-1a EC2 probe and reference endpoint Deployed; actual Local Zone and HTTP reply verified
Honolulu us-west-2-hnl-1a EC2 probe and reference endpoint Deployed; actual Local Zone and HTTP reply verified

Brisbane, Adelaide, Canberra, Hobart, Noumea and Suva remain gaps in this AWS regional/Local Zone design. Edge presence, Direct Connect presence, a nearby parent region and a requested CF placement do not establish executable probe coverage in those cities. Retain useful CF measurements under their observed execution city.

Sources: AWS Regions, available Local Zones, Auckland region, and live account ListRegions/DescribeAvailabilityZones responses. The Auckland region avoids depending on the support-gated Auckland Local Zone.

Load balancers and cost evidence

An ALB is a reference endpoint; it cannot execute the outbound probe. For the three Local Zone cities, one EC2 instance can supply both functions. An additional ALB would not add geographic coverage, so it is not selected by default. A fixed ALB response remains an alternative where its endpoint behaviour supplies a useful independent comparison.

Live AWS Pricing GetProducts rates, Linux shared t3.medium, without free allowances:

Location EC2 US$/hour ALB base US$/hour ALB capacity US$/LCU-hour gp2 disk US$/GB-month
Perth 0.0713 0.0775 0.0125 0.228
Honolulu 0.0645 0.1800 0.0125 0.260
Los Angeles 0.0499 0.0270 0.0096 0.120

Three continuously running instances cost US$138.16 for 744 hours, before disks, addresses and network. Eight GiB gp2 per instance adds US$4.86/month. Running all three for two hours per day instead costs US$11.51 compute over 31 days, but references are unavailable outside those windows; retained disks and any retained addresses still incur charges. The deployment configuration must choose and enforce its operating schedule rather than quote intermittent pricing for continuous resources.

Regional Lambda first-tier x86 duration rates are US$0.0000166667/GB-second in Sydney, Melbourne, Singapore, Jakarta, Hyderabad and Tokyo; Auckland is US$0.0000175 and Hong Kong US$0.00002292. At 128 MiB, 120 seconds and 96 runs/day for 31 days, eight regions total approximately US$6.27 compute. These are compute figures, not a complete bill or a duration guarantee for a larger target panel.

Raw regional/Local Zone price responses are retained privately as successor-184-aws-expanded-pricing-20260923-0347.json. Additional S3/log prices and outbound-network prices are retained in successor-184-aws-service-pricing-20260923-0355.json and successor-184-aws-network-pricing-20260923-0358.json.

Selected operating plan and total estimate

Use continuous Local Zone references during the initial 30-day collection period, with measurement rounds every 15 minutes at all eleven sources. Regional probes use Lambda, 256 MiB and at most 300 seconds per invocation. The three Local Zone EC2 instances run the same bounded collector and reference endpoint. The scheduled end and instance stop must be implemented and verified before charged compute is deployed; evidence is retained afterward. No NAT gateway, provisioned Lambda concurrency, paid secrets service or extra ALB is included.

The initial panel contains seven R2 targets: the five inconclusive stock buckets, previously verified pool-r2-i8u5efd5 as a regression case, and EU reference-f6k2q9v3 as an independently foreign control. Previous verification is not independent Australian ground truth. Each round runs ten synthetic PUT/HEAD/GET trials per target and ten reads per configured AWS reference. It creates no application payload and uses its own object prefix. Both request order and failures are retained. A slow or failed target must not prevent other targets or origins collecting results.

Use one conditional slot claim per source, no measurement retries within a slot, and at most eleven evidence writes and 256 KiB total evidence per source/slot. Save completed target results separately so a later interruption does not discard earlier observations. Restrict reference replies to small fixed synthetic payloads; logs contain bounded summaries. The qualification integration below adds an authenticated read endpoint to Sydney only; HTTP requests cannot start collection. The implementation and live acceptance must establish these bounds; this table is not a claim that a cloud billing hard cap exists.

Conservative 31-day estimate without free allowances, excluding tax:

Component Basis US$
Three Local Zone EC2 instances t3.medium rates above, 744 hours each 138.16
Root volumes 8 GiB gp2 each at the three local rates 4.86
Three public IPv4 addresses 744 hours each at $0.005/hour 11.16
Eight regional Lambda probes 2,976 invocations each, 300 seconds, 0.25 GiB, region-specific first-tier rates 31.34
Lambda requests and Scheduler Scheduled invocation rates; no free allowance assumed 0.04
S3 writes, reads and evidence storage Up to 360,096 writes; 2,618,880 regional-reference reads; under 9 GiB new evidence 4.50
Operational logs Allow 1 GiB at the highest observed ingestion rate plus retention 0.85
Network allowance Synthetic traffic, TLS overhead, evidence traffic and deployment/bootstrap downloads 10.00
R2 operations 2,291,520 Class A and 4,583,040 Class B, rounded to whole millions 15.30
Estimated total Includes allowances; actual runtime and traffic determine charges 216.21

Use US$230 as the operating estimate with margin for this bounded initial configuration, under the owner's full in-scope provisioning approval. It is not an account-wide spending limit. Recompute if instance availability, disk size, target count, duration or cadence changes. No estimate from the historical two-region proposal is used. Retained disks, evidence and any retained addresses continue to incur charges after compute stops; release unneeded addresses during dependency-checked cleanup.

Qualification integration adds capacity for one explicitly selected stock or canary candidate alongside the seven-target panel; nine targets or a missing baseline/control are refused before collection. At eight targets throughout all 2,976 monthly rounds, eleven origins make at most 2,618,880 R2 Class A and 5,237,760 Class B operations. At the same recorded rates and whole-million rounding, R2 becomes $15.66 and the estimate becomes $216.57, within the existing $230 operating allowance. Compute deadlines, cadence, evidence-write/size limits and stop dates stay fixed. The retained canary canary-r2-o74bamza occupied the eighth slot for the 06:30 verification. The eighth slot follows the current operator-selected target; the seven baseline targets remain present. Live readback of the 06:30 AEST slot found all eleven first-trial records with the same provider creation identity, eight targets, successful canary PUT/HEAD/GET/cleanup and no reference failures. After the fixed five-minute deadline, the authenticated reader returned all 110 canary/control trial records with zero record or operation failures (332,924 bytes). This round established measurement enrollment. Automatic operator/restock enrollment subsequently merged in #371 and is deployed; it updates the existing panel without adding infrastructure.

The operator configuration accepts one optional bucket name, reads its current provider creation identity and distributes only synthetic-prefix credentials. Saved trials retain that identity. A direct configuration call without an extra target selects the seven-target baseline. The deployed renewal reads and preserves the selected extra target; operator checks select their exact pending candidate before measurement. Unavailable sources remain gaps. Enrollment alone never grants qualification.

The existing Sydney Lambda gains an authenticated, read-only /evidence Function URL. Its role reads only results/* across the eleven evidence stores, in addition to its existing collection permissions. The endpoint cannot choose a caller URL, slot, object key or favourable subset: it reads all ten trial objects at all eleven origins for the latest slot whose five-minute collection deadline has elapsed, returning failures alongside valid observations. It selects only the requested candidate and the EU control, with original object keys and SHA-256 hashes. Source collectors do not call this endpoint. Its unavailability therefore affects evidence readback, not collection or retained results. The shared measurement token remains a secret; AWS credentials and private configuration are never returned.

Allow a further $2 for up to 1,000 such reads in the initial period, using the maximum Lambda duration and recorded request/network rates. The revised bounded-use estimate is $218.57, still within $230. This request-count assumption is not an enforced public billing cap. The Sydney reader was deployed and verified at 06:14 AEST on 23 September: an unauthenticated request returned 401; an authenticated request returned all 110 records from the fixed completed slot, with zero record errors. ADR-0045 now uses this authenticated readback as the AWS source, assessed separately from CF native measurements.

S3 observed first-tier Standard rates range from $0.023 to $0.02625/GiB-month, writes from $0.0047 to $0.005775 per thousand, reads from $0.00037 to $0.000462 per thousand. Logs ingestion is $0.50–$0.80/GiB. Regional internet egress is $0.09–$0.132/GiB. Public sources: IPv4 pricing, Scheduler pricing, R2 rates and rounding. Account region enablement has no compute charge; live instance offerings and launch capacity still need checking after Local Zone opt-in.

Delivery boundary

Deploy through Alchemy under ADR-0029. ADR-0043 and the narrowly checked measurement-resource scope extend the earlier ADR-0028 Sydney/Melbourne restriction for these named stacks. Protected application storage and public-entry restrictions remain separate from synthetic measurement infrastructure. No account-wide policy relaxation is required.

Under ADR-0021, CF-native, AWS external-operation and AWS-reference collection stay independently usable. The combined assessment consumes labelled observations from those sources; it does not silently treat an external S3 request as a native-binding operation. Replies and retained records identify source, actual origin, target, operation, time, samples and failures. CF-only, AWS-only and combined assessment modes must disclose their available evidence and uncertainty.

ADR-0025 keeps scope, schedules, resource limits and evidence validation executable. ADR-0033 preserves exact resource identity and verification history. ADR-0045 is the deployed qualification rule; ADR-0042 remains the interpreter of its historical records. The successor preserves contradictions and uncertainty, and does not rewrite old verification.

The scoped plan policy is implemented with focused acceptance and refusal tests. The registered drq-aws-access stack enabled the four required account regions through the existing deployment gate at 03:59:36 AEST. Fresh EC2 readback succeeded in all four regions, reporting three available Availability Zones each. The deployment log and readback are retained privately as successor-184-aws-access-deploy-20260923-0357.log and successor-184-aws-enabled-readback-20260923-0400.json. Sydney probe compute was deployed at 04:16:46 AEST. AWS readback confirms the active Lambda in ap-southeast-2, 256 MiB/300 seconds, and the enabled 15-minute schedule ending 23 October. The first invoked run completed all ten trials, retaining every trial in private S3; the first trial completed PUT/HEAD/GET and cleanup for all seven R2 targets. All eight regional stacks are now deployed. Fresh readback confirms every Lambda is active in its declared AWS region, all eight schedules are enabled with the specified end date, and all four S3 public-access blocks are enabled in every evidence bucket. The collector/policy/deployment suite passed 23 tests and infrastructure type checking passed. All three Local Zone probes are now deployed and collecting. Combined qualification was subsequently merged and deployed in #371; activation evidence records its live checks.

Regional deployment uses one private Alchemy code-artifact bucket per region in addition to the evidence bucket. Eight small Lambda archives fit within the existing S3 storage allowance; no bucket base charge is added. Both bucket types are registered in their measurement stack.

Credential setup uses the established Cloudflare Temporary Credentials API with the exact synthetic prefix. Live checks confirm permitted synthetic writes/metadata/deletes and denial outside that prefix for all seven targets before upload to AWS. The documented local JWT method was rejected by the live R2 endpoint (InvalidArgument: X-Amz-Security-Token); no parent credentials were uploaded. The API maximum lifetime is seven days. Initial credentials expire 29 September UTC. Daily renewal is now installed and its first all-eleven-source run succeeded; the runtime rejects expired credentials. Normal scheduled collection calls neither the credential API nor a CF measurement Worker.

First regional panel: all eight verified Lambda regions completed ten trials each (80 saved records, 1,680 successful PUT/HEAD/GET operations and 560 successful synthetic-object cleanups). Records are in each city’s private evidence bucket under results/1790100900000/; the operator readback and aggregate are retained privately under aws-panel-1790100900000/. Sydney had the lowest median PUT for all six non-EU targets, ranging from 143 to 185.5 ms, versus 229.5–326 ms from Auckland. The EU control had a materially different profile. This supports the Sydney hypothesis; it does not by itself establish every replica’s location or constitute admission. Sydney’s initial reference panel preceded the other deployments; the next scheduled panel provides contemporaneous complete AWS-reference coverage.

Melbourne, Auckland and Hyderabad exposed a pinned Alchemy bug: an absent previous Function URL was treated as an existing URL and the unsupported regional URL API was called. The dependency patch preserves the existing Cloudflare compatibility fix, avoids deleting a URL that never existed, and treats only the exact unsupported-operation response as no URL during read/list. Other access-denied errors still fail. Actual AWS CLI readback reproduced that regional API response. Post-patch deployments passed in Melbourne, Auckland and Hyderabad; fresh schedule readback is enabled in all three. The installed runtime/source patch, unchanged dependency version and lockfile hash are retained in this worktree.

Local Zone account access is now managed by the three registered drq-probe-per, drq-probe-lax and drq-probe-hnl stacks. Each owns its exact LocalZoneAccess setting and bounded compute/reference stack. Perth, Los Angeles and Honolulu opt-ins completed; initial Perth/Honolulu reconciliation exceeded one minute, so bounded convergence was extended to five minutes. All three compute instances have since launched in the exact declared zones. The account lists t3.medium in all three exact zones; this is an offering check, not a guarantee of launch capacity.

Before launch, image inspection found that the current Amazon Linux 2023 defaults to gp3 while Perth and Honolulu support gp2. Canonical-owned Ubuntu 22.04 images provide the priced 8 GiB gp2 root without changing the shared instance provider: ami-0f7c190973eb47b09 in ap-southeast-2 and ami-07b3d2f97d89e29a4 in us-west-2, both published 4 September 2026. Image owner, root mappings and exact IDs are retained privately in successor-184-local-zone-ubuntu-ami.json. The existing monthly disk estimate therefore remains applicable. Perth, Los Angeles and Honolulu HTTP references returned their exact local zones. Perth retained ten complete trial records with IMDS-derived zone identity. Its cloud-init took over seven minutes after a reboot, then completed without errors; the collector and 23 October OS stop timer are active. All three saved records attest their actual zones, and all AWS stop schedules target the exact instance at 00:00 UTC on 23 October. SSM readback confirms both remaining OS timers are also active, with no cloud-init errors.

The expanded collector measures the three Local Zone HTTP references as well as eight regional S3 references. Operator configuration discovers each exact tagged EC2 instance and zone through AWS; collector records retain that instance identity, endpoint failures and missing configurations. Local Zone S3 evidence storage is in the parent region and is never used as a city reference. Wrong reference bodies, oversized replies, wrong configured zones and failed requests cannot count as successful calibration. Sixteen focused tests passed with infrastructure type checking before rollout.

Daily credential renewal is registered on this Mac as com.comms-id.drq-184-aws-renew, using the existing named AWS profile and machine-local CF credential. It renews each source independently, retests synthetic-prefix restrictions, and stops issuing credentials at the collection end date. The CF parent credential never goes to AWS. Collection itself is scheduled and retained in AWS; the Mac must run successfully at least once within each seven-day credential period. The initial renewal run finished at 05:08 AEST with exit 0 and successful renewed configurations for all eleven cities.

At 05:11 AEST, the expanded reference collector rollout had completed in all eleven stacks. The first retained all-city evidence download contains 330 trial records and 6,930 successful PUT/HEAD/GET operations, with no failed target operations. Sydney has the lowest median PUT for every non-EU target; the independent EU control is fastest from Los Angeles and Honolulu. The exact raw files and aggregate remain private under paired-aws-20260923-0509/. Fresh 17-origin CF rounds for the five inconclusive buckets and the regression bucket are running alongside AWS collection; requested placements that execute elsewhere remain explicitly labelled. New reference-panel success still needs live readback.

The first expanded panel exposed artifact ownership drift in Los Angeles: after Honolulu's bucket was added, Alchemy selected it for new artifacts and IAM, while the existing host bootstrap still read Los Angeles's bucket. The retained panel shows that failure explicitly and that ten other origins continued saving successful R2 operations. The pinned patch now prefers the current stack/stage's owned artifact bucket before the historical shared fallback. Three offline tests exercise the installed lookup, including the exact Los Angeles/Honolulu ordering case; the full focused collector suite passes 19 tests. Live readback confirmed Los Angeles now reads its own artifact bucket, serves its exact-zone reference and saves new trial records. The S3 bucket declarations now supply explicit stack/stage ownership tags; unlike the EC2 resources, those tags were not automatic.

The real stack-loader regression also found eager credential resolution in the custom Local Zone provider. It now captures the lazy AWS environment and resolves account/region only during resource operations. The all-entrypoint loader regression passed after the fix; live plans for all three Local Zones passed without creates or deletes.

The CF observational capture now keeps useful measurements when placement differs, with requested and observed cities recorded separately. Live post-deployment checks on 23 September returned 110 samples each for requested Perth observed in Sydney and requested Adelaide observed in Brisbane, with stable final traces and no failures. GET validation compares the full fresh payload. These observations are not claims of Perth or Adelaide execution. Two preceding repeated six-bucket rounds retained 204 origin attempts and 12,860 samples; the newer producer also retains observations the older producer labelled wrong-origin.